Invest1 publisher3 min readPublished
Both wallet makers say AI is shortening the distance between finding a bug and using one, which makes the pace of their own coordinated disclosure the number worth pricing, and the only loss they cite belongs to a rival vendor.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Late January 2026 to June 3 is about 125 days [1][3][1], and that is the figure worth holding in an episode whose participants say the attacker's clock is speeding up [8]. Ledger Donjon spent that window coordinating with Tropic Square, which makes the TROPIC01 secure element sitting inside Trezor's Safe 7 [1][2], and the coordination paid a dividend the original finding did not contain: the chip vendor itself turned up a second attack path, this one touching PIN-related functions [4]. Two findings for the price of one disclosure.
Exposure during those 125 days was close to nil, because the attack wants the device in hand and a laboratory bench to put it on, with no remote or supply-chain route [5]. Which is where price and value come apart. Priced as a threat, this is worth very little; valued as a precedent, it is what Trezor's chief executive, Matej Zak, calls the model the industry should hold itself to [14].
The only dollar figure anywhere near the story is the roughly $116mn tied to Coldcard wallets in July 2026, which Ledger cites as its illustration of weak entropy meeting stronger attack tools [9][10], and which landed about a month after the Trezor disclosure went public, at a different vendor [2]. The material does not say an AI tool was used in it [4]. So the compression argument [8] rests, on this evidence, on an assertion by two firms with a shared interest in industry-wide reporting standards [15], carried by analogy rather than measurement.
What Ledger bought with Donjon's time is worth naming: hours spent on a competitor's silicon are hours not spent on its own secure elements, which are proprietary, unlike Tropic Square's openly designed part [13]. The return is not a sale. It is a reporting norm that would route other people's findings through vendors first, plus a line that Ledger's lab found this before anyone else did, while Trezor gets to say two of its three independent layers were never in play [6][3]. Both readings hold at once, and the record supports the sincere one at least in part, since cross-company disclosures between these two go back to 2018-2019 [11] and a voltage-glitch finding followed the same protocol in 2025 [12].
The reported loss column for this flaw is empty [7][5], which is the strongest thing either company can say and also the reason the standards pitch is hard to price: a process that works leaves no invoice. On the evidence supplied, the push is real engineering with a press release stapled to it, and the test is a count of signatures. A written framework with a named coordination window and a third company on it would mean the default changed. If the next cross-vendor finding arrives as a conference talk with no vendor coordination and no framework text behind it, the model was a statement two competitors made on a week when the facts flattered both.
Ranked by verification strength, evidence, and original report placement.
In late January 2026, Ledger Donjon identified a laser fault-injection attack on the TROPIC01 chip, a secure element manufactured by Tropic Square and integrated into the Trezor Safe 7 wallet.
Ledger Donjon is Ledger's security research arm; Ledger and Trezor are both crypto hardware wallet makers and competitors.
The vulnerability was publicly disclosed around June 3, 2026, after Ledger coordinated with Tropic Square directly.
During the coordinated disclosure process, the chip's manufacturer uncovered an additional attack path affecting PIN-related functions.
The attack requires physical possession of the device and access to specialised laboratory equipment; there is no remote or supply-chain risk associated with the flaw.
Trezor said user funds and backups remain safe because the TROPIC01 chip is one of three independent security layers in the Safe 7, so exploiting that chip would leave the other layers in place.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One trade outlet, no advisory to check it against
The January find, the June date, the PIN-related second path and the three-layer defence all reach us through Crypto Briefing restating what Ledger and Trezor say. No Tropic Square advisory, chip errata or Donjon technical write-up sits behind the account, and no second newsroom has retested the dates or the severity.
Three dated events, nothing to install
We can put dates on the discovery, the disclosure and the Coldcard loss Ledger cites. What nobody supplies is a firmware version, a patch, an affected-unit count or any evidence that a Safe 7 owner's device changed state, which leaves the real-world footprint of this flaw at zero in both directions.
Bench-only attack borrowing a rival's dollar figure
Crypto Briefing supplies its own deflation a few paragraphs below the alarm: the attack needs the wallet in hand and laser equipment, and Trezor's answer is that two of the three layers were never touched. The urgency comes instead from an AI argument neither firm measures and from $116 million lost at Coldcard, a figure with no connection to this chip.
Both sides gain from this version of events
Ledger's lab found the weakness in a competitor's silicon and comes out looking rigorous and gracious at once. Trezor gets to advertise that its three-layer design held. The joint call for disclosure standards parks the argument that most divides them, since Tropic Square's chip is openly documented and Ledger's secure elements are not.
Plausible account, unverified in every particular
Fault injection against secure elements is ordinary research and nothing here strains belief, which is different from being checked. A single trade publication wrote this up in September about events running from January to July, with the vendors supplying the dates, the severity and the reassurance.
security
A machine found the bug and set the clock: Ledger disputes TestMachine's timeline1 publisher
invest
Order data ShipMonk promised to delete pushes Trezor's breach count to 80,7002 publishers
product
Apple's report cap blocked a seven-person firm with a patched Mac bug to its name1 publisher
invest
Coinkite now makes Coldcard owners roll dice, after $130M walked out of air-gapped wallets1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026